CVE-2026-82764: Medium severity vulnerability
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users who are logged in to an affected Contec product and then view a specially crafted page are exposed. Exploitation requires user interaction because the logged-in user must load the attacker-controlled page.
Does an attacker need an account on the affected product?
No privileges are required for exploitation according to the provided vector. The attacker relies on the victim already being authenticated to the affected product.
What impact can exploitation have?
Successful exploitation may cause unintended operations to be performed through the logged-in user's session. The provided impact assessment indicates integrity impact, with no stated confidentiality or availability impact.